81trust / 100

Email Security

by HALOWERK Agent Tools in Security & trust

x402 APIPassing, checked 4 h ago

Prüft MX, SPF, DKIM, DMARC, MTA-STS, TLS-RPT, BIMI, TLS am Mailserver und DNSSEC einer Domain und leitet daraus Spoofing-Risiko, Punktzahl und Befunde ab. Jeder Befund trägt einen fertigen DNS-Datensatz zum Einfügen statt einer Empfehlung in Prosa. Rein lesend: kein Versand, keine Testmail, keine Relay-Nutzung.

POST https://tools.halowerk.com/v1/email/security

Last 30 days

All checks passedSome failedAll failedNot checked
Uptime
100%
Response time
40 ms typical, 40 ms slowest 5%
Last check
4 h ago
Next check
any minute now

How to call it

# See the payment challenge (nothing is charged)
curl -i -X POST "https://tools.halowerk.com/v1/email/security" \
  -H "content-type: application/json" \
  -d '{"dkim_selectors":["default","google","selector1"],"domain":"example.com"}'
import { wrapFetchWithPayment } from "@x402/fetch";
import { x402Client } from "@x402/core/client";
import { ExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";

const client = new x402Client().register(
  "eip155:8453",
  new ExactEvmScheme(privateKeyToAccount(process.env.AGENT_KEY)),
);
const pay = wrapFetchWithPayment(fetch, client);

// Not sure it's safe to pay? Preflight it first for $0.005:
// GET https://toolvet.app/api/v1/check?url=https%3A%2F%2Ftools.halowerk.com%2Fv1%2Femail%2Fsecurity
const res = await pay("https://tools.halowerk.com/v1/email/security", {
  method: "POST",
  headers: { "content-type": "application/json" },
  body: JSON.stringify({"dkim_selectors":["default","google","selector1"],"domain":"example.com"}),
});
console.log(await res.json());

Example input

{
  "dkim_selectors": [
    "default",
    "google",
    "selector1"
  ],
  "domain": "example.com"
}

Example output

{
  "checked_at": "2026-08-06T12:00:00.000Z",
  "checks": {
    "dmarc": {
      "detail": {
        "de": "Kein DMARC-Datensatz.",
        "en": "No DMARC record."
      },
      "status": "fehlt",
      "value": {
        "record": null
      }
    },
    "spf": {
      "detail": {
        "de": "SPF endet auf \"~all\" (softfail).",
        "en": "SPF ends in \"~all\" (softfail)."
      },
      "status": "schwach",
      "value": {
        "all_mechanism": "~all",
        "dns_lookups": 4,
        "record": "v=spf1 include:_spf.google.com ~all"
      }
    }
  },
  "domain": "example.com",
  "findings": [
    {
      "fix": "_dmarc.example.com. 3600 IN TXT \"v=DMARC1; p=none; rua=mailto:[email protected]; adkim=r; aspf=r; pct=100\"",
      "severity": "kritisch",
      "title": {
        "de": "DMARC fehlt",
        "en": "DMARC missing"
      },
      "why_it_matters": {
        "de": "Ohne DMARC entscheidet jeder Empfänger selbst, was mit einer gefälschten Mail geschieht.",
        "en": "Without DMARC every receiver decides for itself what happens to a forged message."
      }
    }
  ],
  "score": 41,
  "spoofing_risk": "hoch"
}

Security scan

  • No findings. We scan names, descriptions and tool definitions for hidden instructions and other prompt-injection patterns.

Recent checks

WhenResultHTTPTimePrice
4 h agoPassed40240 ms$0.002